Powershell Command in Registry Data
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2023 10:48 PM
For the last few hours we have been seeing an increasing number of 'Powershell command in registry data' findings.
They all look the same and report something similar:
File: | taskhostw.exe e6370920…58402728 |
Registry Key: | \USER\S-1-5-21-1514197063-1296195755-1265796959-7856\SOFTWARE\Microsoft\Windows\CurrentVersion\AppListBackup\ListOfTaskBackedUpTiles_2361862998 ListOfTaskBackedUpTiles_2360852998 |
Registry Set | \USER\S-1-5-21-1514197063-1296195755-1265796959-7856\SOFTWARE\Microsoft\Windows\CurrentVersion\AppListBackup\ListOfTaskBackedUpTiles_2361862998 |
- Labels:
-
AMP for Endpoints
-
Endpoint Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-14-2023 12:17 AM
No nothing to worry but it obviously looks like the behavioral monitoring mapped the way it was added to known tactics and techniques. Is there a new or updated group policy up and running that manipulates existing scheduled tasks? Not sure but I thought there's a way to mute alerts the get triggered.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-15-2023 05:52 AM
We have opened a TAC on this. They are still investigating but it seems that more than one customer has been affected.
I am curious about the cause of this
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-15-2023 07:20 AM
By now it seems to get evolving with the last ms windows updates (patchday)...:-D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2023 06:32 AM
Did Cisco get back to you on this? I started seeing this in our environment this morning.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2023 06:49 AM
No, not yet. We opened a TAC almost two weeks ago, but got no response other than "we're investigating"... 🤷
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-27-2023 05:42 AM
Hi There,
Just wondering if you have heard anything yet? I have had a couple of alerts for the same issue.
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-28-2023 12:08 AM
> Sep 22: "Talos is currently working on improving the indicators of compromise. Unfortunately I do not have information about estimated time of putting this on production, but once I found out I will let you know immediately."
> Sep 27: "Engineering already improved the signatures so you should not see such False Positives anymore. Please confirm that everything is fine regarding this issue."
So supposedly it's fixed, but we're still getting alerts today...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-28-2023 02:37 AM
Thanks for the info, fingers crossed it's fixed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2023 07:54 AM
We still see those alerts. Does anyone have news?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-12-2023 09:39 AM
We are still getting the alerts even though TAC has assured us several times that the problem is really fixed now...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-26-2023 09:02 AM
This popped
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-06-2023 06:42 AM
I saw this on one of our hosts 10 times in the last month:
Registry Key: \USER\S-1-5-21-3581115410-45963113-3647916999-49065\SOFTWARE\Microsoft\Windows\CurrentVersion\AppListBackup\TotalListOfLastBackedUpTiles_2343873105
Let's hope this really is fixed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-21-2023 06:19 AM
Still continuing to pop up for us, only a couple workstations though. Last one was on November 18th on version 8.1.3.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-23-2023 06:44 AM
We have multiple customers and this only pops up for users of a specific customer (specific org). TAC says it's fixed with the latest definition updates but it's not. I have sent them some data and they are investigating.
